Skip to main content
S 1656 115th Congress Senate Health

Medical Device Cybersecurity Act of 2017

Introduced: July 27, 2017 Introduced by: Blumenthal, Richard Democratic · Connecticut See on congress.gov
This bill died when the 115th Congress ended
It never became law before the 115th Congress (2017–2018) adjourned, and bills don't carry over to the next Congress. It would have to be reintroduced. You can still save it for reference, but it won't receive updates.
 Everywhere this bill has been 2 steps
Introduced
In committee
Reported out
Passed House
Passed Senate
To President
Became law
Jul 27, 2017
Read twice and referred to the Committee on Health, Education, Labor, and Pensions.
Jul 27, 2017
Introduced in Senate
 Ask about this bill AI · grounded in the bill text

Have a question about what this bill does? Ask in plain English; the answer is drawn from the bill's actual text and official record, and it'll tell you when something isn't in the text rather than guess.

AI answers can be imperfect; always confirm against the full bill text.

 Plain-English summary Congressional Research Service

Medical Device Cybersecurity Act of 2017

This bill amends the Federal Food, Drug, and Cosmetic Act to require the Food and Drug Administration (FDA), in coordination with others, to create a cybersecurity report card for devices that have network or Internet connectivity, connect to an external drive or external media, or have any other cyber capability.

Report cards must contain specified information, including: (1) information pertaining to the essential elements described in the most recent version of the Manufacturer Disclosure Statement for Medical Device Security, (2) a cybersecurity risk assessment conducted by the manufacturer or third party, and (3) whether the device is capable of being accessed remotely.

A cyber device manufacturer must include a report card in any premarket notification or application for premarket approval. The FDA shall provide a copy of a device's report card if requested by a health care industry entity or an entity with a valid interest in the report card. 

The bill establishes procedures, including notifications to providers and patients, for manufacturers when cyber devices are remotely accessed or no longer going to be sold. Fixes and updates to cyber devices must be free of charge for specified time periods.

The bill expands the responsibilities of the Department of Homeland Security's Industrial Control Systems Cyber Emergency Response Team to include investigating cybersecurity vulnerabilities of cyber devices that may cause harm to human life or the significant misuse of personal health information, and coordinating device-specific responses.

What's happening now July 27, 2017

Read twice and referred to the Committee on Health, Education, Labor, and Pensions.

 Bill text 1 version

Source documents hosted by congress.gov.

 Committees of jurisdiction 1
Cite this page click to expand
APA
U.S. Congress. (2026). S. 1656: Medical Device Cybersecurity Act of 2017. 115th Congress. Open America. https://openamerica.io/bill/115-S-1656/
MLA
"S. 1656: Medical Device Cybersecurity Act of 2017." 115th Congress, 2026, Open America, https://openamerica.io/bill/115-S-1656/.
Bluebook (legal)
S. 1656, 115th Cong. (2026), https://openamerica.io/bill/115-S-1656/.
Markdown link
[S. 1656: Medical Device Cybersecurity Act of 2017](https://openamerica.io/bill/115-S-1656/)
Report a problem